# k8s.io/client-go@v11.0.0+incompatible — Threat Briefing Medium risk — threat briefing for go package k8s.io/client-go@v11.0.0+incompatible. Capabilities, risk paths, and what to check. - **Ecosystem:** go - **Latest version:** v11.0.0+incompatible ## Risk - **Level:** medium - **Summary:** Held pending complete intel — waiting on advisory data ## Capability Summary | Capability | Level | |---|---| | install scripts | none | | network access | client | | filesystem | both | | shell execution | none | ## Capabilities ### Other - Code execution at module-load time (Go init) [common] - Long encoded payload [common] - External vendor / cloud integration [common] - Network call to suspicious target [common] - Network call to an untrusted destination [common] ### Environment - Environment variable access [common] ### Network - Network client [common] ## Key Signals - **** ## Trust Signals ### Code Safety - No dynamic code execution - No access to sensitive paths - No network activity during install ## Maintainer ## Recommended Action Audit capabilities before use in production.